Earlier quoted context omitted.
A part of the issue is IMO that browsers have become ridiculously bloated everything-programs. You could take about 90% of that out and into dedicated tools and end up with something vastly saner and safer and not a lot less capable for all practical purposes. Instead, we collectively are OK with frosting this atrocious layer cake that is today's web with multiple flavors of security measures of sometimes questionabl…
Are you saying we should make a A large set of really simple tools that each do one thing really really really pedantically well? This might be what's needed to break out of the current local optimum.
Google flags Immich sites as dangerous
271–280 of 713 posts
Re: Google flags Immich sites as dangerous
#272If there are any googlers here, I'd like to report an even more dangerous website. As much as 30-50% of the traffic to it relates to malware or scams, and it has gone unpunished for a very long time. The address appears to be adsense.google.com.
Re: Google flags Immich sites as dangerous
#273If you're going to host user content on subdomains, then you should probably have your site on the Public Suffix List https://publicsuffix.org/list/ . That should eventually make its way into various services so they know that a tainted subdomain doesn't taint the entire site....
Looking through some of the links in this post, I there are actually two separate issues here: 1. Immich hosts user content on their domain. And should thus be on the public suffic list. 2. When users host an open source self hosted project like immich, jellyfin, etc. on their own domain it gets flagged as phishing because it looks an awful lot like the publicly hosted version, but it's on a different domain, and pos…
Re: Google flags Immich sites as dangerous
#274Earlier quoted context omitted.
Yes but that's not a legal argument. You're honor, we hurt the plaintiff because it's better than nothing!
True, and agreed that lawsuits are likely. Disagree that it's short-sighted. The legal system hasn't caught up with internet technology and global platforms. Until it does, I think browsers are right to implement this despite legal issues they might face.
The point I raise is that the internet is international. There are N legal systems that are going to deal with this. And in 99% of them this isn't going to end well for Google if plaintiff can show there are damages to a reasonable degree.
It's bonkers in terms of risk management.
If you want to make this a workable system you have to make it very clear this isn't necessarily dangerous at all, or criminal. And that a third party list was used, in part, to flag it. And even then you're impeding visitors to a website with warnings without any evidence that there is in fact something wrong.
If this happens to a political party hosting blogs, it's hunting season.
Re: Google flags Immich sites as dangerous
#275If there are any googlers here, I'd like to report an even more dangerous website. As much as 30-50% of the traffic to it relates to malware or scams, and it has gone unpunished for a very long time. The address appears to be adsense.google.com.
sites.google.com
Enshitification ensues.
Re: Google flags Immich sites as dangerous
#276Earlier quoted context omitted.
The Honda issue where setting a certain radio station, would brick the infotainment? That good enough?
Never heard of this. Link please?
[0] https://www.soundandvision.com/content/remembering-time-when...
Re: Google flags Immich sites as dangerous
#277Earlier quoted context omitted.
regular cars?
The Honda issue where setting a certain radio station, would brick the infotainment? That good enough?
Not really. Does the car still drive? That sounds like a software bug; hardly indicative that the entire car is held together with duct tape, but a pretty bad bug non the less.
Re: Google flags Immich sites as dangerous
#278I'm fighting this right now on my own domain. Google marked my family Immich instance as dangerous, essentially blocking access from Chrome to all services hosted on the same domain. I know that I can bypass the warning, but the photo album I sent to my mother-in-law is now effectively inaccessible.
No later than last weekend I was comtemplating migrating my family pictures to a self-hosted Immich instance... I guess a workaround Google's crap would be to put an htpasswd/basic auth in front of Immich, blocking Google to get to the content and flagging it.
Btw, folks in the Jellyfin thread tried blocking specifically Google bot / IP ranges (ASNs?) https://github.com/jellyfin/jellyfin-web/issues/4076#issueco... with varying success.
And go through your domain registration/re-review in G Search Console of course.
Re: Google flags Immich sites as dangerous
#279The one thing I never understood about these warnings is how they don't run afoul of libel laws. They are directly calling you a scammer and "attacker". The same for Microsoft with their unknown executables. They used to be more generic saying "We don't know if its safe" but now they are quite assertive at stating you are indeed an attacker.
Imagine if you bought a plate at Walmart and any time you put food you bought elsewhere on it, it turned red and started playing a warning about how that food will probably kill you because it wasn't Certified Walmart Fresh™ Now imagine it goes one step further, and when you go to eat the food anyway, your Walmart fork retracts into its handle for your safety, of course. No brand or food supplier would put up with it…
Re: Google flags Immich sites as dangerous
#280Maybe a dumb question but what constitutes user-hosted-content? Is a notion page, github repo, or google doc that has user submitted content that can be publicly shared also user-hosted? IMO Google should not be able to use definitive language "Dangerous website" if its automated process is not definitive/accurate. A false flag can erode customer trust.
A website where a user can upload "active code". The definition of "active code" is broad & sometimes debatable - e.g. do old MySpace websites count - but broadly speaking the best way of thinking about it is in terms of threat model, & the main two there are: - credential leakage - phishing The first is fairly narrow & pertains to uploading server side code or client javascript. If Alice hosts a login page on alice.…
By preventing newcomers from using this pattern, Google's system is flawed, severely stifling competition.
Of course, this is perfectly fine for Google.